Security Posture Assessment · Australia
The SPA gives you a score, the evidence behind it, and the fixes in the order that matters — graded from your real configuration, never a questionnaire.
Start free · no credentials · a real score in two minutesThe problem
Almost nobody can answer that with a number, let alone prove it. Here's what we hear instead.
We don't know where we stand.
No score, no baseline, no honest picture of what's actually configured across the business.
We don't know how to find out.
The tooling is scattered, the expertise is expensive, and the answer never seems to arrive.
Another questionnaire.
Forty boxes ticked, a number at the end, and not one line telling anyone what to actually fix.
We failed the audit and did it twice.
Walking in without knowing your posture costs findings, rework, and a second audit fee.
Our edge
Every free security check in this market is a questionnaire — you rate yourself, a number comes out, and nothing was ever verified. The SPA reads your actual configuration and shows you the exact setting that failed.
The product
Run against your live environment, each layer builds on the last — and you decide where to stop.
Everything an attacker sees before they touch you: email spoofing, DNS, web and TLS hygiene, exposed services. No credentials required.
Free · two minutesRead-only access to M365, Azure, AWS and Google Cloud. 400+ controls graded from live configuration — not from what someone believes is switched on.
Every finding evidencedYour environment graded against the framework you answer to, requirement by requirement — then kept current, so your score and evidence never go stale.
40+ frameworksEach step is an upgrade, not a restart. Your findings carry forward.
Free external check
The free check is a genuine assessment, not a teaser. In two minutes, with nothing shared, it reads the posture the whole internet can already see.
SPF, DKIM and DMARC. Can somebody send mail as you?
Whether your domain records can be tampered with.
HTTPS, HSTS and the headers that stop common attacks.
Ports and services facing the internet that shouldn't be.
Software versions you're advertising to anyone looking.
The forgotten dev, staging and remote-access hosts that widen your attack surface.
A scored result you keep — whether or not you go further.
Inside the report
Every finding shows the literal misconfiguration pulled from the scan, next to RG Labs' analysis and the remediation that closes it.
Sample report · a real client's identifiers and remediation redacted for privacy
No other free check in this market can print that middle column.
Compliance
Someone is always asking you to prove your security. The SPA turns that question into a document you can hand over the same day.
We assess the technical and cloud controls of these frameworks — the half that can be proven from configuration. The policy, process and people half we'll tell you about honestly, and scope separately. No consultant pretends a scan makes you certified.
Show me your Essential Eight maturity.
Scored control by control, with the evidence behind every grade.
Complete this renewal form.
Answered from real configuration, not guesses that bite at claim time.
Are we secure?
One posture score they understand, tracked over time.
Pass our due diligence.
Tender questionnaires answered with proof instead of promises.
Framework availability varies by cloud — CIS and ISO 27001 across all four; PCI-DSS, HIPAA and MITRE on AWS, Azure and GCP; NIST across AWS. We'll confirm exactly what applies to your environment before you buy.
Why RG Labs
The person who reads your configuration is the one who explains it — and can fix it.
We grade what we can prove and attest the rest. Nothing came from a checkbox.
You know the price and the deliverable before we start. No open-ended retainers.
We hand the work back documented. Keep us on if it helps, drop us if it doesn't.
You'll know your posture. You'll have the evidence. You'll know what to fix first.
Fixed scope. Fixed price. No lock-in.
Priced by how many clouds you run, not by the tier. All prices AUD, ex-GST — access unlocks on payment.
Rather skip the check and talk to us first? Get in touch →
The full external assessment — every finding with its fix, PDF included.
Start free →External + up to 2 clouds. The right pick for most Australian mid-market teams.
Start free →Everything in Complete, plus engineer attestation of the controls scanners can't see and a live findings & remediation call. Built for regulated and board-driven buyers.
Start free →The report kept live: weekly re-scan, drift alerts and an always-on portal.
2 clouds $390/mo · 4 clouds $590/mo. Annual — 2 months free.
Everyone's rolling out AI; almost nobody can prove theirs is secure. We audit your Microsoft 365 Copilot rollout and your AWS & GCP AI services — Bedrock, SageMaker and Gemini — for the oversharing, weak controls and exposed models that quietly leak data. Graded to the AWS AI Security Framework, delivered as its own report. $5,000 standalone · +$2,500 added to a Standard or Complete report
Beyond four environments or multi-entity groups, talk to us.
Two minutes, no credentials, a real score at the end. See what the internet can already tell an attacker about you.